
oob_entry
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming…

oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming…

A free, open-source, and cross-platform iDevice management tool

Cross-platform library to parse, modify, and abstract ELF, PE, and MachO executable formats. Supports C++, Python, and Rust APIs with disassembler,…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

iOS platform security & anti-tampering Swift library

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

CVE-2026-28992 IOHIDFamily FastPathUserClient race condition PoC — security research

A simple customization toolbox that utilizes CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.

A privacy-focused iOS app that raises awareness about what native apps can see

This project shows the kind of data a rogue iPhone application can collect.

Cybersecurity Researcher | Apple Security Credit (CVE-2025-43537) | Vulnerability Research & Responsible Disclosure

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

Deterministic kernel exploit based on CVE-2023-32434.

Technical analysis of CVE-2026-28858, a critical buffer overflow in Apple iOS/iPadOS kernel, including exploit flow, mitigation, and defensive coding…

This uses CVE-2025-43407 as exploit and still testing working not gauranteed.

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…